CVE-2023-5136: Incorrect Permission Assignment in the TopoGrafix DataPlugin for GPX

Published Nov 8, 2023
·
Updated

An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.

Affected Software

64 affected components
NI Topografix Data Plugin Gpx=2023
NI Diadem=2014
NI Diadem=2015
NI Diadem=2015-sp2
NI Diadem=2017
NI Diadem=2017-sp1
NI Diadem=2018
NI Diadem=2018-sp1
NI Diadem=2019
NI Diadem=2019-sp1
NI Diadem=2020
NI Diadem=2020-sp1
NI Diadem=2021
NI Diadem=2021-sp1
NI Diadem=2022-q2
NI Diadem=2022-q4
NI Diadem=2023-q2
NI VeriStand=2013-sp1
NI VeriStand=2014
NI VeriStand=2015
NI VeriStand=2015-sp1
NI VeriStand=2016
NI VeriStand=2017
NI VeriStand=2018
NI VeriStand=2018-sp1
NI VeriStand=2019
NI VeriStand=2019-r2
NI VeriStand=2019-r3
NI VeriStand=2019-r3f1
NI VeriStand=2020
NI VeriStand=2020-r2
NI VeriStand=2020-r3
NI VeriStand=2020-r4
NI VeriStand=2020-r5
NI VeriStand=2020-r6
NI VeriStand=2021
NI VeriStand=2021-r2
NI VeriStand=2021-r3
NI VeriStand=2023-q1
NI VeriStand=2023-q2
NI VeriStand=2023-q3
NI VeriStand=2023-q4
NI FlexLogger=2018-r1
NI FlexLogger=2018-r2
NI FlexLogger=2018-r3
NI FlexLogger=2018-r4
NI FlexLogger=2019-r1
NI FlexLogger=2019-r2
NI FlexLogger=2019-r3
NI FlexLogger=2019-r4
NI FlexLogger=2020-r1
NI FlexLogger=2020-r2
NI FlexLogger=2020-r3
NI FlexLogger=2020-r4
NI FlexLogger=2021-r1
NI FlexLogger=2021-r2
NI FlexLogger=2021-r3
NI FlexLogger=2021-r4
NI FlexLogger=2022-q2
NI FlexLogger=2022-q4
NI FlexLogger=2023-q1
NI FlexLogger=2023-q2
NI FlexLogger=2023-q3
NI FlexLogger=2023-q4

Event History

Nov 8, 2023
CVE Published
via MITRE·03:24 PM
Data Sourced
via MITRE·03:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-5136?

CVE-2023-5136 has been classified as a medium-severity vulnerability.

2

What could happen if CVE-2023-5136 is exploited?

Exploitation of CVE-2023-5136 could lead to unauthorized information disclosure.

3

How do I fix CVE-2023-5136?

To remediate CVE-2023-5136, update to the latest version of the TopoGrafix DataPlugin for GPX or any affected software.

4

Which software is affected by CVE-2023-5136?

CVE-2023-5136 affects the TopoGrafix DataPlugin for GPX and several versions of NI DIAdem and NI VeriStand.

5

How can an attacker exploit CVE-2023-5136?

An attacker can exploit CVE-2023-5136 by convincing a user to open a specially crafted data file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203